For those in Cyber GRC who have done technical interviews, do you mind commenting some questions you’ve been asked? In my technical interview I was asked what steps I would take to align a company to a new regulatory framework. Any others? I’m specifically applying for policy management type roles. Thanks in advance!

like
Posting as :
works at
You are currently posting as works at

This was for a role specific to iso 27001 but I have been asked to explain isms like I’m 5 and 35.

How do you best create and illustrate kpis and dashboards to help show senior leadership and auditors effectiveness of the program.

Also been asked to create mock remediation plans for risks and issues based on a scenario and how I would work with teams to measure the effectiveness of the plans

likehelpful

Thank you!

I developed a cybersecurity interview guide which you may find to be a valuable resource. Feel free to DM me to learn more.

like

Ideally...

1. Engage legal to understand and agree on the scope, applicability, and requirements of the regulatory framework
2. Using manual and/or automated methods, conduct a gap analysis against the requirements of the regulatory framework
3. Uncover technical and/or process based gaps and translate gaps into risks
4. Ingest risks into risk management program for ongoing risk management
5. Share all material with the compliance management and internal audit functions for ongoing compliance and internal audit
6. Agree on assurance activities and associated schedule with the compliance management and internal audit functions and execute activities

There is more to be done, but this is at a high-level

likehelpful

Thanks! Great answer.

Related Posts

Hi, There are various opportunities in citi for IT and Non Tech roles in Project management, please DM to send your resume

like

Currently a senior interested in consulting but a mix of coming from a non target and requiring sponsorship has me losing hope. Any recommendations on how to proceed with recruiting? I've been told only MBB will sponsor entry level consultants. I have both VC and Consulting experiences through internships.

Latinx - help! We used this term in our diversity spotlight discussing Hispanic Heritage Month. One individual said that in English a group of Latinos would just be Latins to be gender neutral. I understand the word is controversial but is “Latins” grammatically correct? I assume we should just say Latin Americans, but trying to understand if Latins is also accurate.

like

Experiential Marketing position, remote w/ some travel and 5 years of experience. Any idea of salary range?

like
like

Fishes need your help on decision making, of course it's a regular post,, got offer from accenture for team lead level 9 with fixed ctc of 17.45 LPA + 1.75 joining bonus + 27% variable pay. Is it ok to join to that level and CTC ??

YOE: 6.8
SKILL: SSIS
CTC: 13 LPA Fixed + 10% variable pay

Mindtree fishes still working from home or hybrid started ?

Hey Guys, does anyone know if jp has plans to call people to office full time from next year? I have my joining date as 1st November and want to know if they’ll continue with the hybrid model or no?

Does Cognizant reimburse monthly Broadband expenses?

like

Does adhd cause you to struggle with job performance or satisfaction? I’ve been having a hard time focusing on tasks for long periods of time and have lost interest in my job. It’s discouraging because I’m just a junior and worried that it means I’m not suited to be a cw.

like

I have cleared 3 rounds with Deloitte for PMO Role, have an upcoming final Partner Round, any idea what that is?

like

Does anyone have any advice on how to deal with discrimination as an Asian in the workplace? In my company it seems like it’s a white boys club where and they just promote white ppl because they’re white. And then they have a lower bar for promotions for minorities (traditional minorities likes Hispanics and African Americans). Meanwhile they make Asians do all the work. I am not generalizing that this is how it is everywhere but it definitely is that way in my workplace. Any advice?

likeuplifting

Who to Flex? Julio (vs BUF) or Collins (vs PIT) in .5PPR.

like

What are the main factors folks are considering as they make a decision? Solely ranking, money, just curious! Got into two T20 that are very different but see myself at both.

like

Looking to specialize in privacy and was considering getting the CIPP/CIPM/CIPT. I already have my CISSP and CISA. Is it worth it?

like

Anyone joining PwC AC Banglore on 6th September?
Have you got any mail for a laptop or any onboarding details?

I just accepted an offer for a smaller niche shop in a smaller city and I'm so pumped about it. Hardly a confession, but I don't really have that many people I can share my excitement w/ before I quit

likeuplifting

What are your 2018 goals?

like

If you were to articulate the relationship between change management and value realization, how would you do so? To your mind, is change management responsible for value realization? If so, how do?

like

Persistent Systems Limited or Billdesk or Capgemini
Which one is better?

like

Additional Posts in Cyber Security Bowl

I have a younger family member (almost 13) who is very interested in cybersecurity. How can this person learn and grow in a safe manner if he/she isn’t near a city with youth clubs and etc? Idea is to reinforce ethics, but this material is far too advanced for the parents.

like

Would you expense a speeding ticket on your way to an IR?

funnylike

Accenture or Deloitte for cyber security strategy? Who’s on top?

like

Joining a group that specializes in incident response. Any recommendations on things I can do this summer to prepare on fundamentals/certs?

like

Anyone know what kind of experience or certifications I should be aiming to get if I'm trying to break into a pentest role? I just graduated last year and have about a year of sysadmin experience and am trying to get into it asap. So, I'm already applying/job hunting and probably won't get much replies but. Should I be looking at more security analyst/admin roles first? Going for certs? Getting a masters? Wondering what I can do to improve my chances. TIA

like

HMU for referrals

funny

Any BCG Platinion Cyber folks here?
What kinna work do you guys do? Planning to make the switch after 5 years with Uncle D. Wanna hear from you guys about culture, projects and areas of expertise.

like

Anyone here do post-breach data mining? Being pursued to start a practice line doing this and trying to understand market value.

like

Currently stuck in risk but interested in Cyber. Have done one related engagement from a regulatory perspective. But a lot of posts here making me think it’s harder to break into than I expected (non-technical background). If you had a six sigma green belt / supply chain degree/exp., would you still go through the effort of going into Cyber or take easy risk money being offered / easier transition back to supply chain? 2-3 YOE and trying to decide career course, any advice highly appreciated

like

Is there a demand for privacy professionals? Been seeing this discussed more and more recently

like

We’re hiring across the board at KPMG for cyber / cyber risk work - shoot me a DM if interested. (Pays well!)

likehelpful
like

CCSP (cloud security certification) is it worth to do ?

like

I’m a woman in my mid 20s and constantly face situations where people outside of cyber (still within the company) that I’m dealing with (older men in particular) who always push back against my cyber/technical recommendations even with managers cc’d. I studied, earned certs, and worked hard to get to where I am. Is it bc of my gender and age? In all honesty, I’ve written recommendations that male counterparts voiced in the past that had ZERO pushbacks.

like

Cissp cert is as much hard as it seems? Much more than cisa?

like

Any EY PPMD 🐠 willing to chat/connect? Interested in learning more about the cyber practice. I’m a new campus hire in the Hoboken office. Thanks in advance!

like

Has anyone gone through the deloitte cyber risk interview process recently? How many interviews did you have and how was the process?? Salary?

like

For those who have passed the CIPM exam, what is it like (and how does it compare to the CIPP/US exam)?

Any company is hiring EU citizens and helping with visa? interested in moving to USA. I'm lawyer, cissp, cisa, cipp/e and specialized n data privacy, cybersec ops and risk management with 8+ years exp

Today I passed CIPP/US, and earned Security+ in early August. Interviewing for a cybersecurity role at Deloitte tomorrow! Super excited! Interested to connect with fish at Deloitte, especially Deloitte Global. Thanks!

like

New to Fishbowl?

Download the Fishbowl app to
unlock all discussions on Fishbowl.
That was just a preview…
Sign Up to see all discussions
  • Discover what it’s like to work at companies from real professionals
  • Get candid advice from people in your field in a safe space
  • Chat and network with other professionals in your field
Sign up in seconds to unlock all discussions on Fishbowl.

Already a user?
Login here

Share

Embed this post

Copy and paste embed code on your site

Preview

Download the
Fishbowl app

See what’s happening in your industry
from the palm of your hand.

A phone with Fishbowl app

Scan your QR code to download
Fishbowl app on your mobile

Download app

Sign up for free to view this conversation on Fishbowl

By continuing you agree to Terms of Use and Privacy Policy

Already have an account? Log in

Sign up for free to continue using Fishbowl

By continuing you agree to Terms of Use(New) and Privacy Policy(New)
Messaging rates may apply

Already have an account? Log in

For account settings, visit Fishbowl on Desktop Browser or

General

Legal